CVE-2004-1043 Information
Description
Internet Explorer 6.0 on Windows XP SP2 allows remote attackers to execute arbitrary code by using the \Related Topics\ command in the Help ActiveX Control (hhctrl.ocx) to open a Help popup window containing the PCHealth tools.htm file in the local zone and injecting Javascript to be executed as demonstrated using \writehta.txt\ and the ADODB recordset which saves a .HTA file to the local system aka the \HTML Help ActiveX control Cross Domain Vulnerability.\
Reference
http://archives.neohapsis.com/archives/bugtraq/2004-12/0426.html http://www.kb.cert.org/vuls/id/972415 http://www.us-cert.gov/cas/techalerts/TA05-012B.html https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-001 https://exchange.xforce.ibmcloud.com/vulnerabilities/18311 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1349 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A1963 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A2830 https://oval.cisecurity.org/repository/search/definition/oval3Aorg.mitre.oval3Adef3A3496
Share on: